• No results found

Why it's time to upgrade to a Next Generation Firewall. Dickens Lee Technical Manager

N/A
N/A
Protected

Academic year: 2021

Share "Why it's time to upgrade to a Next Generation Firewall. Dickens Lee Technical Manager"

Copied!
41
0
0

Loading.... (view fulltext now)

Full text

(1)

Why it's time to upgrade to a

Next Generation Firewall

Dickens Lee

(2)

Dell

(3)

Dell SonicWALL’s legacy

1991

1996

2005

2007

2010

2011

2012

Founded Became leading provider of subscription services on optimized appliances Became the leader in unit share for Unified Threat Management Firewall appliances Shipped one million appliances worldwide Named to Visionaries Quadrant, Gartner Magic Quadrant for SSL VPN

(4)
(5)
(6)

Changes in user behavior

Blogging

Facebook

Twitter

IM/Whatsapp

Cloud access

(e.g Dropbox)

Streaming video

(e.g Youtube)

Streaming audio

Downloading files

Freeware

(teamviewer , RDP)

Time spent on

Facebook

was

greater than time spent on

Google

sites for the first time in history.

(comScore, August 2010 )

Together

Facebook.com

and

Google.com

accounted for 14% of

all Internet visits last week.

(Hitwise, March 2010 )

(7)

Impacts to your Business

Virus, Spyware, Trojan, Rootkits, Worm

Spam, Phishing, Spear Phishing

Data Leakage

Classified document, trade secret

Bandwidth abuse, Impact on Network Performance

Populated with non-productive traffic

High latency Bad response time

Productivity increase or decrease

Federal or Industrial Regulatory Compliance issue

(8)
(9)

Next

Generation

Firewall

(10)
(11)

80 = HTTP

443 = HTTPS

Web Traffic

Web Traffic

Stateful Firewall

Protection centered around IP, ports & protocols

Allow/Deny in any application over 80/443

To a traditional firewall, all “web” traffic looks legitimate

Do not inspect every port (Customize apps)

Allow Trojans, Rootkits, Malware into the network

(12)

Application Chaos

Who is to say for you what apps are important or not you?

Unimportant Apps

(13)

Next Generation Firewall Technology

1.

Firewall - Stateful Packet Inspection

2.

Intrusion Prevention

– The front-line network defense against application attacks

3.

Application Identification & Visualization

– Can’t control what you can’t see

4.

User Identification through Single Sign On (SSO)

– Correlate network traffic with users

5.

Application Control

– Granular control (Allow Facebook, Block Social Gaming)

6.

SSL Decryption

– Don’t allow threats to tunnel through encrypted channels

(14)

Dell SonicWALL Next-Generation Firewall

Unacceptable Apps Acceptable Apps Critical Apps Malware Blocked Application Chaos Identify Ingress Reassembly-Free Deep Packet Inspection

(15)

Network Traffic Visualization

Real-time Traffic Breakdown

User Traffic Consumption

Identify P2P Traffic

(16)

Identify and Control Applications

Application

Library with over

4200 unique

Application Uses

Granular Control

Allow Facebook, Block

BitTorrent

Allow Chat, Block File Transfer

-

Group/User Based

-

Schedule Based

(17)

How Traditional Firewall & IPS fail:

security/performance tradeoff

Force administrators to choose between

security and performance

Admins often wind up turning off

security when performance suffers

Slow networks hurt productivity

(18)

Highly Efficient

Single-Pass RFDPI

Security Engine

Proven & Proprietary Reassembly Free Deep Packet Inspection

Preprocessors Postprocessors TCP Reassembly Policy Decision API

Deep Packet Inspection Engine (Anti-Malware, IPS, Application)

Pattern Definition Language Interpreter

Signature Signature

Input Packet Output Packet

NGFW Integrated Architecture:

Low-Latency Ultra-Scalable Single Pass Deep

Packet Inspection Engine

(19)

Linearly Scalable on a Massively Multi-Core

Architecture

1 Core 96 Cores

Cavium

cpu custom built to understand network

communications at hardware level (TCP acceleration;

compression/decompression/encryption etc)

Parallel processing for multiple data streams

(20)
(21)

Dell Sonicwall NFGW solution

VPN IPS Users Servers Firewall Antivirus Antispam URL Filters Proxy Application

Dell Sonicwall NFGW

Functions with performance guarantee

Single Sign On

URL web control

Application control

(22)

Dell

(23)

Dell SonicWALL Next-Gen Firewalls &

Unified Threat Management Firewalls

SuperMassive E10000 Series Data Centers, ISPs

E-Class NSA Series Medium to large organizations NSA Series Branch offices and medium sized organizations TZ Series Small and

E10200 E10400 E10800

NSA E8500 NSA E6500 NSA E5500 NSA E8510

(24)

Dell SonicWALL SuperMassive™ E10000

Text

• SuperMassive E10800 running SonicOS is the highest overall protection Next-Gen Firewall recommended by NSS Labs in the 2012 Next-Gen Firewall Security Value Map

• Proven SonicOS architecture is at the core of every SonicWALL firewall from the SuperMassive™ E10800 to the TZ105

• Detects, classifies and controls over 4,200 unique apps • Powerful IPS, Multi-gig performance

• Management/visualization of traffic • RFDPI technology

• SSL traffic inspection

• High availability: A/P, A/A, StateSync, clustering

Comprehensive

Inspection

The Technology

• 96 processor cores • 40 Gbps Firewall Inspection • 30 Gbps IPS

• 30 Gbps Application Intelligence and Control

(25)

Management and Reporting

Scrutinizer

Flow Analytics

for

SonicWALL firewalls,

Analyzer

Reporting & Analytics

for

SonicWALL firewall,

GMS 7.0

Reporting & Analytics,

Policy Management,

Monitoring

for

(26)
(27)

GMS 7.0 & Analyzer -

Next Generation Reporting

• Near real-time

(28)

GMS 7.0 & Analyzer –

Application Traffic Analytics

(29)

GMS 7.0 & Analyzer –

User Centric Reporting

(30)
(31)

What do the

3rd party

(32)

The NSS Security Value Map

Summary of 2012 NGFW

testing results from

www.nsslabs.com

4 Quadrants

-

Recommended

-

Caution

-

2xNeutral

Final Product Rating near

the name of the product

Lines signify corrections due

to major failures

(33)

NSS Test Highlights

Neutral

Caution

(34)
(35)

Dell SonicWALL

SuperMassive E10800

(36)

Threat Coverage by Vendor & Date

SonicWALL vs. Palo Alto Networks v. CheckPoint

(37)

UTM Firewall 2012 Magic

Quadrant (March 2012)

SonicWALL was positioned in

the Leaders Quadrant for

2012

Fast-Forwarding Firewall Face-Off

(April 2012)

Best Overall Performance for NGFW

(38)

ICSA Labs Enterprise Firewall Certification

(39)

Dell SonicWALL

NSA E-Class E7500

“…

was not susceptible to

attacks launched inbound

or outbound to or through

the product, including

fragmentation and trivial

(40)

Data Center: US

• Up-to-date anti-virus & IPS signatures

• Deep-packet-inspection firewall with application

intelligence & IPS

• Anti-Spam / email security

• Multiple layers of protection

• Security awareness training

(41)

Thank You

References

Related documents